Skip to content
This repository was archived by the owner on Sep 22, 2025. It is now read-only.

8.1 Reporting Security Concerns

David Samuel edited this page Feb 12, 2024 · 4 revisions

The policy

Report security vulnerabilities or suspicious activities immediately to the appropriate contact within the Organisation or follow the established incident reporting procedures. (Does not include dependant bot alerts).

The Implementation

  • Who to raise to?
    1. Your team.
    2. Your Grade 7 technical or non technical.
    3. Line Manager or Countersigning manager.
    4. Grade 6 responsible for your work.
    5. Any SLT members.
  • If your management chain isn't working you can raise security incidents you are worried about to:
    1. (DRAFT)SIRA, SOC or cyber security?
  • If you do not feel you got the right answer or still have concerns you can utilise the Civil Service Whistleblowing policy.

Clone this wiki locally